Data processing agreement
Version of 13 September 2026. Earlier versions are available on request.
Required by Article 28(3) of the GDPR whenever one party processes personal data on another’s behalf. It was referred to in the terms and the privacy notice before it existed, which is a gap worth naming rather than quietly closing: without this document, both of us were in breach of Article 28, not just us.
This agreement is incorporated into the terms of service and takes effect when you create an account. No signature is required, and you may request a countersigned copy at any time.
1. The parties and their roles
You — the freelancer, agency or business using Livery — are the controller. Lauridsen Software is the processor.
Lauridsen SoftwareLundgårdsparken 327490 AulumDenmarkCVR: [TO BE SUPPLIED] — CVR numbersupport@liveryhq.com · liveryhq.comFor your own account data the roles are reversed and we are the controller; that processing is described in the privacy notice and is not governed by this agreement.
Where you research businesses and build sites for clients, you decide which businesses to research, what goes on each site and who to contact. Those are the decisions that make you the controller, and they are not ours to make.
2. Subject matter, duration, nature and purpose
- Subject matter: providing the Livery platform — lead research, website generation, hosting, and client billing where used.
- Duration: for as long as your account exists, plus the retention periods in clause 9.
- Nature and purpose: storage, retrieval, organisation, enrichment from public sources, transmission to the sub-processors listed, and deletion.
3. Categories of data and data subjects
- Data subjects: the businesses you research and their owners — including sole traders, who are natural persons; your clients’ staff; and people who submit a contact form on a site you publish.
- Personal data: names, business and personal contact details, addresses, trade and registry information, website assessments, site content you or your client supply, and the content of enquiries.
- Special categories: none are required or requested. Do not put them into site content or lead notes. If you do, you do so as controller and this agreement does not make it lawful.
4. Our obligations
- We process personal data only on your documented instructions. Your use of the product is the instruction; anything else will be in writing. If we believe an instruction breaches data protection law we will say so before acting.
- Everyone with access is bound by confidentiality, and access is limited to those who need it to operate or support the service.
- We implement the measures in clause 7 and keep them under review.
- We assist you — taking into account the nature of the processing and what is available to us — with data subject requests, with security, with breach notification, and with data protection impact assessments where one is required.
- We make available the information needed to demonstrate compliance with Article 28 and allow audits under clause 10.
5. Sub-processors
You give general written authorisation for the sub-processors listed at /legal/subprocessors. We impose the same data protection obligations on each of them by contract, and we remain fully liable to you for their performance.
We will notify account holders by email at least 30 days before a new sub-processor begins processing. You may object on reasonable data protection grounds within that period. If we cannot offer a reasonable alternative, you may terminate the affected part of the service without penalty and receive a refund for the unused portion of the period you have paid for.
6. International transfers
Some sub-processors are outside the EEA, and the sub-processor page says which and on what basis. Most significantly, the database is currently hosted in the United States. Transfers rely on the EU–US Data Privacy Framework where the recipient is certified and on Standard Contractual Clauses otherwise, with the supplementary measures set out in each provider’s terms.
You should treat the database’s location as a fact relevant to your own compliance, not merely ours. We tell you plainly because you cannot assess a transfer you have not been told about, and because your controller obligations do not disappear into ours.
7. Security measures
Article 32 requires measures appropriate to the risk. Ours, stated specifically enough to be checked:
- Encryption in transit (TLS) for all connections, including to the database.
- Encryption at rest for the database and for stored files.
- Passwords stored as salted hashes using a memory-hard function, never in plain text or recoverable form.
- Session cookies that are HTTP-only,
Secure,SameSite-restricted and carry the__Host-prefix in production. - Tenant isolation enforced on every query by organisation, and server-side authorisation on every write.
- Outbound requests are guarded against server-side request forgery, including on every redirect hop.
- A Content Security Policy on the platform and on every generated site.
- Every change to a site is snapshotted before it is applied, so accidental or malicious modification is recoverable.
- Audit logging of authentication and administrative events, retained 24 months.
- Automated dependency updates and least-privilege credentials.
We do not claim any system is completely secure, because none is. We claim these specific measures, and you can hold us to them.
8. Personal data breaches
We notify you without undue delay after becoming aware of a personal data breach affecting data we process for you, and in any case within 48 hours, with the nature of the breach, the categories and approximate number of records, the likely consequences and the measures taken. The 72-hour notification to the supervisory authority is yours to make as controller; we give you what you need to make it, and time to do it.
9. Return and deletion
You can export your data at any time from the product, without asking and without being paid up. On termination we delete personal data processed on your behalf within 90 days, except where retention is required by law — accounting records are kept five years under the Danish Bookkeeping Act. Backups age out on their own cycle and are not restored for other purposes.
10. Audit
We will answer reasonable written questions about our compliance with this agreement within 30 days, and provide any third-party security reports we hold. Where that is genuinely insufficient, you may audit at your own cost, no more than once a year unless a breach or a supervisory authority requires otherwise, with 30 days’ notice, at a time that does not disrupt the service, and subject to confidentiality.
11. Liability and precedence
The limitations of liability in the terms of service apply to this agreement, except that nothing limits either party’s liability to a data subject or to a supervisory authority under Article 82. Where this agreement and the terms conflict on data protection, this agreement wins.
12. Law
Danish law, and the courts of Denmark, without prejudice to a data subject’s rights to bring proceedings where they live.
Questions about this agreement, or a request for a countersigned copy: privacy@liveryhq.com.